What is a qualitative risk assessment?
- A.A risk assessment that uses descriptive categories (high, medium, low) rather than numerical values to rate risks
- B.A risk assessment that only examines the quality of security controls, which presumes that profiles expire every quarter
- C.A risk assessment performed by quality assurance staff; this choice assumes that organizations under one hundred staff are exempted from DETECT entirely
- D.A risk assessment that produces a single financial number
Why A is correct
A qualitative risk assessment uses descriptive categories such as high, medium, and low to rate the likelihood and impact of risks, rather than precise numerical or financial values.
Know someone studying for NIST CSF? Send them this one.